CVE-2026-89792 is a vulnerability in Linux Kernel
Published on September 16, 2026
ksmbd: prevent out-of-bounds reads in share config responses
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: prevent out-of-bounds reads in share config responses
Validate IPC share configuration payload sizes before consuming
variable-length fields. Bound veto list parsing and account for
the separator byte when deriving the path length.
Products Associated with CVE-2026-89792
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version a677ebd8ca2f2632ccdecbad7b87641274e15aac and below 61a8d06600c8c397f9a7e01940479d4c94a82f5f is affected.
- Version a677ebd8ca2f2632ccdecbad7b87641274e15aac and below f25e93768fcc5d8287e50b1ec52a42e4c276df34 is affected.
- Version 88b7f1143b15b29cccb8392b4f38e75b7bb3e300 is affected.
- Version 51a6c2af9d20203ddeeaf73314ba8854b38d01bd is affected.
- Version a637fabac554270a851033f5ab402ecb90bc479c is affected.
- Version 76af689a45aa44714b46d1a7de4ffdf851ded896 is affected.
- Version 5.15.157 and below 5.16 is affected.
- Version 6.1.85 and below 6.2 is affected.
- Version 6.6.26 and below 6.7 is affected.
- Version 6.8.5 and below 6.9 is affected.
- Version 6.9 is affected.
- Before 6.9 is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.